VYPR
Unrated severityNVD Advisory· Published Jun 14, 2007· Updated Apr 23, 2026

CVE-2007-3208

CVE-2007-3208

Description

CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests to (1) register.pl or (2) profile.pl that write CRLF sequences to a .vars file. NOTE: this can be leveraged to execute arbitrary code.

Affected products

1
  • cpe:2.3:a:yabb:yabb:2.1:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.